Privacy Policy
Last Updated: June 28, 2026
This Privacy Policy explains how Hildebrand Ligtas (“we,” “our,” or “us”) collects, uses, stores, shares, and protects information when you use our ERPNext-based application, website, and related services located at:
https://erp.hildebrandligtas.com
This Privacy Policy also explains how our application uses Google OAuth and Google APIs, including Google Calendar integration, when users choose to connect their Google account.
By using our application, you agree to the practices described in this Privacy Policy.
1. Application Description
Our ERPNext-based application is a business management system used for project management, task tracking, meetings, calendar events, customer management, inventory, purchasing, sales, accounting, timesheets, document management, approvals, and related business operations.
The application may allow authorized users to sign in using Google OAuth and, when enabled, connect with Google services such as Google Calendar. This integration helps users create, view, synchronize, and manage calendar events related to ERPNext meetings, projects, tasks, and business schedules.
2. Information We Collect
We collect information necessary to operate, secure, and improve our application.
2.1 Account Information
When you create or use an account, we may collect:
- Name
- Email address
- Username
- Company or organization name
- Role, department, or user permissions
- Profile information configured inside ERPNext
- Authentication information required to manage your account
2.2 Business and ERP Data
Depending on how your organization uses the application, ERPNext may store business-related data such as:
- Projects
- Tasks
- Issues
- Meetings
- Calendar events
- Customers
- Suppliers
- Employees
- Timesheets
- Sales records
- Purchase records
- Inventory records
- Accounting records
- Attachments and documents uploaded by users
- Approval records and workflow information
2.3 Google Account Information
When you choose to sign in with Google or connect your Google account, we may receive limited information from Google, depending on the permissions you approve, such as:
- Your Google account email address
- Your name
- Your Google profile identifier
- Basic profile information
- Google Calendar data, if calendar integration is enabled and approved by you
We only request Google data that is necessary for the features shown in our application.
2.4 Google Calendar Data
If you authorize Google Calendar access, our application may access, create, update, or synchronize calendar-related information such as:
- Calendar event title
- Event date and time
- Event description
- Event location
- Event attendees
- Meeting or project-related event details
- Calendar identifiers necessary for synchronization
We use Google Calendar data only to provide calendar-related ERPNext features, such as creating project meetings, synchronizing ERPNext events with Google Calendar, and notifying participants of scheduled events.
2.5 Technical and Usage Information
We may collect technical information such as:
- IP address
- Browser type
- Device type
- Operating system
- Login timestamps
- Activity logs
- Error logs
- Security logs
- Pages or features accessed within the application
This information is used for security, troubleshooting, auditing, system performance, and application improvement.
3. How We Use Information
We use collected information for the following purposes:
- To create and manage user accounts
- To authenticate users, including through Google OAuth
- To operate ERPNext business features
- To manage projects, meetings, tasks, events, documents, and approvals
- To synchronize ERPNext events with Google Calendar, when authorized
- To send notifications related to meetings, projects, tasks, approvals, or system activity
- To provide customer support
- To monitor application performance and security
- To prevent fraud, unauthorized access, or misuse
- To comply with legal, contractual, and regulatory obligations
- To improve the reliability and functionality of the application
We do not use Google user data for advertising.
4. Use of Google APIs
Our application uses Google APIs only to provide user-facing features that are clearly available inside the application, such as Google Sign-In and Google Calendar integration.
Our use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only access Google user data after you grant permission through Google OAuth.
- We only use Google user data to provide or improve user-facing features in our application.
- We do not sell Google user data.
- We do not use Google user data for advertising.
- We do not transfer Google user data to third parties except as necessary to provide the application, comply with the law, protect security, or with your consent.
- We do not allow humans to access Google user data unless necessary for security, support, legal compliance, or when you explicitly request support involving that data.
5. Google OAuth Permissions and Scopes
Depending on the features enabled, our application may request Google OAuth permissions such as:
5.1 Basic Profile and Email
Used to allow users to sign in with Google and identify their ERPNext account.
Purpose:
- Authenticate users
- Display the user’s name or email in the application
- Link the Google account to the ERPNext user account
5.2 Google Calendar Access
Used only when calendar integration is enabled.
Purpose:
- Create ERPNext meeting events in Google Calendar
- Add event participants
- Synchronize meeting or project schedules
- Update or remove calendar events created through the application
- Help users manage business schedules from ERPNext
We do not request Google Calendar access unless the feature is required and authorized by the user.
6. How We Share Information
We do not sell, rent, or trade your personal information.
We may share information only in the following limited situations:
6.1 With Your Organization
If your account is part of an organization using our ERPNext system, authorized administrators and permitted users within that organization may access information according to their ERPNext roles and permissions.
6.2 With Service Providers
We may use trusted third-party service providers to operate our application, such as hosting providers, email providers, storage providers, analytics providers, or infrastructure providers.
These providers may process information only as necessary to provide services to us and must protect the information appropriately.
6.3 For Legal and Security Reasons
We may disclose information if required to:
- Comply with applicable laws or legal processes
- Protect our rights, users, or systems
- Investigate fraud, abuse, or security incidents
- Enforce our agreements or policies
6.4 With Your Consent
We may share information when you or your organization explicitly authorizes us to do so.
7. Data Storage and Security
We use reasonable administrative, technical, and organizational safeguards to protect information from unauthorized access, loss, misuse, alteration, or disclosure.
Security measures may include:
- Access controls
- User permissions and role-based access
- Password protection
- OAuth-based authentication
- Secure server configuration
- HTTPS encryption
- Database access restrictions
- Logging and monitoring
- Backup and recovery procedures
However, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.
8. Data Retention
We retain information only for as long as necessary to provide our services, comply with legal obligations, resolve disputes, maintain security, and enforce agreements.
Retention periods may depend on:
- Your organization’s ERPNext configuration
- Legal or accounting requirements
- Backup schedules
- Security and audit requirements
- Whether the user account remains active
Google user data is retained only as long as needed to provide the authorized Google-connected feature, unless a longer retention period is required by law or legitimate business obligations.
9. Data Deletion
You may request deletion of your personal information or Google-connected data by contacting us at:
privacy@hildebrandligtas.com
Upon receiving a valid deletion request, we will take reasonable steps to delete or anonymize the applicable information, unless we are required to retain it for legal, accounting, security, or legitimate business reasons.
If your account is managed by your organization, some deletion requests may need to be handled by your organization’s system administrator.
You may also disconnect our application from your Google account at any time by visiting your Google Account permissions page.
10. User Choices and Controls
You may have the ability to:
- Access your account information
- Update your profile
- Change your password
- Disconnect Google OAuth access
- Disable Google Calendar integration
- Request deletion of your information
- Request export of your information, where applicable
Your organization’s ERPNext administrator may control certain access, retention, and deletion settings.
11. Revoking Google Access
You can revoke our application’s access to your Google account at any time through your Google Account security settings.
After access is revoked:
- We will no longer be able to access new Google data.
- Existing ERPNext records created before revocation may remain in the system unless deleted by you, your organization, or an authorized administrator.
- Calendar synchronization features may stop working.
12. Cookies and Similar Technologies
Our application may use cookies or similar technologies to:
- Keep users signed in
- Maintain secure sessions
- Remember preferences
- Protect against unauthorized access
- Improve application performance
You can control cookies through your browser settings. Disabling cookies may affect application functionality.
13. Children’s Privacy
Our application is intended for business and organizational use. It is not directed to children under the age of 13 or the minimum age required by applicable law.
We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, please contact us so we can take appropriate action.
14. International Data Processing
Your information may be processed and stored in countries other than your own, depending on our hosting providers, infrastructure, and service providers.
By using the application, you understand that your information may be transferred to and processed in countries where data protection laws may differ from those in your location.
15. Legal Basis for Processing
Where applicable, we process personal information based on one or more of the following legal bases:
- Your consent
- Performance of a contract
- Legitimate business interests
- Compliance with legal obligations
- Protection of security and prevention of misuse
For Google OAuth and Google API access, we process Google user data based on your authorization and consent through Google’s OAuth consent process.
16. Data Accuracy
We rely on users and organizations to provide accurate and up-to-date information. You may update your account information through the application or by contacting your administrator.
17. Third-Party Links and Services
Our application may contain links to third-party websites or services, including Google services.
We are not responsible for the privacy practices of third-party services. We encourage users to review the privacy policies of any third-party services they use.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our application, legal requirements, or business practices.
When we update this policy, we will revise the “Last Updated” date above. Continued use of the application after changes means you accept the updated policy.
19. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or how your information is handled, contact us at:
Name: Hildebrand Ligtas
Website: https://erp.hildebrandligtas.com
Email: privacy@hildebrandligtas.com
20. Google API Limited Use Disclosure
Our application’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not sell Google user data. We do not use Google user data for advertising. We only use Google user data to provide or improve user-facing features that are clearly available in our application.
21. Summary of Google Data Usage
When you connect your Google account, we may use your Google account information and Google Calendar data only for the following purposes:
- To allow you to sign in using Google OAuth
- To connect your Google account with your ERPNext user account
- To create calendar events from ERPNext meetings or schedules
- To add event participants to Google Calendar events
- To synchronize ERPNext events with Google Calendar
- To update or remove events that were created or managed through the application
We do not use Google data for unrelated purposes.
22. Data Deletion Request
To request deletion of your Google-connected data or personal information, email:
privacy@hildebrandligtas.com
Please include:
- Your name
- Your email address used in the application
- The organization or ERPNext account related to the request
- A short description of the data you want deleted
We will process valid requests within a reasonable time, subject to legal, security, and business retention requirements.